Senior Security Application Engineer
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Company Description
Join a multibillion-dollar global company that brings together amazing technology, people, and operational scale to become a powerhouse in the memory industry. Headquartered in Rancho Cordova, California, Solidigm combines elements of an established, successful technology company with the spirit, agility, and entrepreneurial mindset of a start-up. In addition to the U.S. headquarters and other facilities in the U.S., the company has international presence in Asia, Europe, and the Americas.
Solidigm will continue to lead the world in innovating new Memory technologies with aspirations to be the #1 NAND memory company in the world. At Solidigm, we view problems as opportunities to define innovative solutions that hold the power to change the world and unleash the potential technological needs that the future holds.
At Solidigm, we are One Team that fosters a diverse, equitable, and inclusive culture that embraces individual uniqueness and empowers us to bring our best selves to deliver excellence in support of Solidigm's vision and mission to be the go-to partner for optimized data storage solutions. You can be part of the takeoff of an innovative business that develops cutting-edge products, delivers strong business value for customers, provides an engaging workplace for its employees, and serves a greater impact on the world.
This is a golden opportunity for the right applicant to join us and help design, build, and lead Solidigm. We want a diverse team of dedicated professionals who will not just be Solidigm team members but contribute to how we shape the future of the organization. We are seeking applicants who will grow and thrive in our culture; be customer inspired, trusting, innovative, team-oriented, inclusive, results driven, collaborative, passionate, and flexible.
Job Description
Agentic Detection & Response Engineering Define and own detection coverage strategy — establish detection standards, naming conventions, and quality criteria for the SOC and Product Security program.
Map the threat landscape to MITRE ATT&CK TTP coverage; prioritize detection development against real adversary behaviors and threat intelligence; maintain ATT&CK coverage heatmaps and track MTTD and false positive rates as operational KPIs.
Build and ship agentic detection and response — own the full lifecycle from threat use case through detections-as-code, automated triage, and production agentic response workflows.
Design and govern AI agent identity and delegation — architect the end-to-end lifecycle for non-human identities operating in the security environment, including scoped delegation, audit logging, and kill-switch controls.
Apply MITRE ATLAS adversarial ML techniques to threat-model all agent deployments; validate guardrails against OWASP Top 10 for LLM Applications and OWASP Top 10 for Agentic AI.
Product Security & Cryptographic Infrastructure Support and enhance Solidigm's Product Security & Code Signing platform — the cryptographic foundation for firmware signing, device identity (EJBCA/PKI), attestation (COSE/CBOR, LMS, PQC/ML-DSA), and unlock (CRAM/ADU) across all product lines.
Build and maintain automation for signing pipelines, HSM health monitoring, certificate lifecycle management, and access provisioning workflows integrated into CI/CD.
Contribute to PQC adoption — ML-DSA, LMS/LMOD, CNSA 2.0+, and OCP 3.0+ readiness — by developing and shipping the automation and tooling that operationalizes these standards.
Own and evolve the security data platform supporting cryptographic governance: signing telemetry, KPI dashboards, audit logging, and anomaly detection for signing infrastructure.
Architect and govern AI agent integrations within the code signing and cryptographic operations environment — scoped identity, delegation controls, and human-oversight mechanisms for any automation touching signing or key operations.
Application & Product Security Integration Embed across firmware engineering, CI/CD, and manufacturing teams — delivering security controls, pipeline integrations, and attestation automation directly in their environments.
Integrate security requirements (SAST, SBOM generation and validation, attestation signing, supply-chain controls) across firmware build and release pipelines.
Validate security controls through adversary emulation and purple team exercises; close coverage gaps identified through testing and operational feedback.
Operate within and strengthen NIST AI RMF, OWASP Top 10 for LLM Applications, NIST FIPS 140-3, NSA CNSA 2.0+, OCP 2.5 to 3.0+, and ISO 27001/SOX ITGC governance gates.
Technical Leadership & Expectations Lead security program components and define detection, automation, and cryptographic governance standards — not just execute them.
Shape the product and application security engineering roadmap through threat modeling,